Rust Dependency Security¶
Source: hooks/ways/softwaredev/code/supplychain/depscan/rust/rust.md
Frontmatter
| Field | Value |
|---|---|
description |
Rust dependency security, cargo audit, unsafe blocks, build script risks |
vocabulary |
cargo audit Cargo.lock Cargo.toml unsafe build.rs crate crates.io rustsec advisory |
refire |
0.15 |
scope |
agent, subagent |
Scanning¶
Rust-Specific Risks¶
build.rsruns at compile time. It's a build script with full system access — read it for unfamiliar crates.unsafeblocks bypass the borrow checker. Not inherently malicious but worth reviewing in unfamiliar code:grep -rn 'unsafe' src/- Proc macros are compile-time code execution. Crates with
proc-macro = trueinCargo.tomlrun arbitrary code during compilation. - Rust's supply chain is generally healthier than npm/PyPI — smaller ecosystem, stronger cultural norms around safety — but not immune. Typosquatting and maintainer compromise still happen.